Clop Ransomware Targets Windchill and FlexPLM in Data Theft Attacks

www.news4hackers.com-clop-ransomware-targets-windchill-and-flexplm-in-data-theft-attacks-clop-ransomware-targets-windchill-and-flexplm-in-data-theft-attacks

Summary: The Clop ransomware group is exploiting a critical vulnerability in PTC Windchill and FlexPLM systems, leading to data exfiltration and ransom demands.

Vulnerability Details

The Clop ransomware group has initiated a new data exfiltration campaign targeting PTC Windchill and FlexPLM systems, leveraging a critical vulnerability to access sensitive enterprise data. The threat actors are exploiting a flaw classified as CVE-2026-12569, which allows unauthorized execution of malicious code on exposed instances of the software. This vulnerability, described as a high-severity unsafe deserialization issue with a CVSS score of 9.3, enables attackers to deploy JSP webshells for remote command execution and data extraction.

CVE-2026-12569 Exploitation

Cybersecurity firm ReliaQuest confirmed that the group has been actively exploiting the flaw, with threat actors using JSP webshells to exfiltrate confidential information from compromised product lifecycle management (PLM) platforms. The firm noted that the tactics align with previous Cl0p operations targeting enterprise applications and critical data repositories. While the specific actor behind the attacks remains unverified, the techniques observed match the group’s historical methods.

Response and Mitigation

Extortion efforts have escalated, with affected organizations receiving ransom demands via email addresses such as support@cryptohox.com. This address is part of a broader strategy by the Clop gang to rotate communication channels during new campaigns. PTC addressed the vulnerability by releasing patches starting June 17, though the company did not confirm active exploitation at the time. Subsequent advisories urged customers to review systems for indicators of compromise (IOCs) and apply updates promptly.

CISA and BSI Actions

The Cybersecurity and Infrastructure Security Agency (CISA) responded to the threat by adding CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. U.S. federal agencies were directed to secure their Windchill and FlexPLM instances within three days. In Germany, the Federal Office for Information Security (BSI) took immediate action, contacting PTC customers late at night to emphasize urgent patching. This follows a similar response in March 2026 to a related flaw, CVE-2026-4681, which was also deemed critical for Windchill and FlexPLM systems.

Clop’s History and Impact

ReliaQuest advised PTC users to apply available patches and isolate affected systems if compromise is suspected. The firm recommended collecting forensic evidence, rotating credentials, and restoring services only after thorough remediation. A PTC spokesperson did not immediately respond to inquiries about the incident. PTC Windchill and FlexPLM are widely used PLM platforms in industries such as aerospace, automotive, and medtech. These tools manage product development cycles, making them attractive targets for cybercriminals seeking high-value data.

Past Campaigns and Targets

PTC reports over 30,000 global customers, including more than 1,500 retail and brand entities using FlexPLM. Clop’s history of data theft campaigns includes breaches of Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, and MOVEit Transfer. The group’s 2025 exploitation of an Oracle EBS zero-day flaw led to data exfiltration from institutions like Harvard University and American Airlines. Stolen information is typically published on the group’s dark web leak site.

Security Recommendations

The U.S. Department of State has offered a $10 million reward for intelligence linking Clop’s activities to a foreign government. Security experts emphasize proactive measures, as 54% of breaches go undetected for extended periods. Organizations are urged to conduct regular vulnerability assessments and implement layered security strategies to mitigate risks.

According to ReliaQuest, PTC users should apply available patches and isolate affected systems if compromise is suspected. The firm recommended collecting forensic evidence, rotating credentials, and restoring services only after thorough remediation.



About Author

en_USEnglish